Globya Information Technologies · Since 2000 0850 432 55 13 info@globya.com.tr
SearchCtrl K Start a project

Business Email · Guide

Get your email delivered with SPF, DKIM and DMARC.

Receiving servers ask the same question about every incoming email — does this message really come from the company that sent it? SPF, DKIM and DMARC answer that question in your domain's DNS records.

Three settings, three jobs

These three settings don't replace one another; they work together.

SettingWhat it doesIf it's missing
SPFLists which servers are allowed to send email in your nameOther servers can send email in your name, and your email looks suspicious
DKIMAdds a digital signature tied to your domain to every messageThere's no proof the message wasn't altered on the way
DMARCSays what to do with email that fails SPF and DKIM, and sends reportsFake email isn't blocked, and you can't see who is using your name

SPF record

SPF is a single TXT record added to your domain's DNS. For example, if only your own mail server and a newsletter tool send email, the record looks roughly like v=spf1 mx include:newsletter-tool.com ~all. Common mistakes here are having two separate SPF records on the same domain, leaving sending systems such as invoicing software or a CRM off the list, and adding so many includes that the record goes over its limit.

DKIM signature

For DKIM, your mail server generates a key pair. The private key stays on the server, and the public key is added to DNS as a TXT record. Every outgoing email is signed, and the receiving server verifies the signature against the key in DNS. If more than one system sends email in your name, each of them needs its own DKIM setup.

DMARC policy

The DMARC record is added under the name _dmarc, and moving in stages is the safest approach:

  1. Monitoring. You start with v=DMARC1; p=none; rua=mailto:dmarc@yourcompany.com; no email is blocked, reports are simply collected.
  2. Quarantine. Once the reports confirm all legitimate sending sources, p=quarantine sends failing email to spam.
  3. Reject. If everything looks good, p=reject has fake email rejected outright.

This sequence keeps an overlooked sending source (for example, automatic invoice emails from your accounting software) from suddenly being blocked.

Why can't this wait any longer?

Since 2024, Google and Yahoo have expected SPF, DKIM and DMARC together, especially from domains that send email in high volumes; other major providers have taken similar steps. Even for companies that send little email, these settings directly affect delivery rates. On top of that, DMARC is the most effective technical safeguard against fraud attempts that send fake payment requests in your company's name.

Checklist

  • Does the domain have a single SPF record that includes all sending sources?
  • Do the mail server and other sending tools sign with DKIM?
  • Is there a DMARC record, and are the reports being read?
  • Have protective records been added for your secondary domains that don't send email?

Frequently asked questions

Once these are set up, will our email never land in spam?

Delivery rates improve noticeably, but content, sending frequency and server reputation also matter. Identity settings are a basic requirement, not the only factor.

Do these settings affect our website?

No. These records concern email only; they don't affect how your website works.

For general DNS management, see the domain and SSL page; for the big picture, see the business email page, or reach out to us to have your domain checked.

Project wizard

Describe your SPF, DKIM and DMARC needs in 3 minutes

No typing needed: answer 10 short questions with buttons and our team will get back to you with a roadmap made for you.

Get started

The next project could be yours

Let us run your digital work from a single point.

Let us hear your needs in a short phone call and prepare a free preliminary analysis report for your website.